Skip to content

Conversation

@MSAdministrator
Copy link
Member

@MSAdministrator MSAdministrator commented Nov 24, 2025

Description

Discovers the use of telegram within the link analysis content of a URL. If detected, it's highly likely to be a phishing site.

Associated hunts

@MSAdministrator MSAdministrator self-assigned this Nov 24, 2025
@MSAdministrator MSAdministrator requested a review from a team as a code owner November 24, 2025 18:10
@github-actions github-actions bot added hunting-required Hunts needed to validate rule efficacy test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules labels Nov 24, 2025
@MSAdministrator
Copy link
Member Author

Running manual hunts now in multiple environments.

@MSAdministrator
Copy link
Member Author

I actually did run these but realized it was link analysis so will advise a new plan for these.

@MSAdministrator
Copy link
Member Author

New Hunt

@MSAdministrator
Copy link
Member Author

Closing this for this #3707

Mostly because we can detect this without the use of link analysis

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant